- Description
- Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks
- Source
- mandiant-cve@google.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- CRITICAL
- mandiant-cve@google.com
- CWE-321
- Hype score
- Not currently trending
KnowledgeDeliver の脆弱性 CVE-2026-5426:実環境での悪用を Mandiant が警告 https://t.co/jOywxW67Dk KnowledgeDeliver の脆弱性 CVE-2026-5426 の原因は、システムの設定ファイルで管理される暗号鍵 (machineKey) が、複数の環境で共有さ
@iototsecnews
1 Jun 2026
83 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-5426 zero-day in KnowledgeDeliver LMS exploited via hardcoded https://t.co/jaGYvH4XOK machine keys for ViewState deserialization attacks. Mandiant confirms Godzilla web shell deployment and Cobalt Strike beacons. #DFIR_Radar https://t.co/Cmy6PCIkKa
@DFIR_Radar
28 May 2026
67 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
KnowledgeDeliverにゼロデイ攻撃 認証なしで悪用可能なCVE-2026-5426 Godzilla web shell設置 全顧客環境で共有されたhttps://t.co/uRKtvxGxAV machine keyが原因 Mandiantが2025年末の攻撃対応で確認 #サイバーセキュリティ #ゼロ
@WatcherN12588
27 May 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2026-45659 2 - CVE-2026-5426 3 - CVE-2026-48172 4 - CVE-2024-12802 5 - CVE-2026-8945 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
27 May 2026
99 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🩹マイクロソフト、SharePointの深刻なRCE脆弱性にパッチ(CVE-2026-45659) ⚠️ハッカーがKnowledgeDeliverのゼロデイを悪用し、Webシェルとバックドアを展開(CVE-2026-5426) 〜サイバーアラート5月27日〜 https://t.co/X6yz
@MachinaRecord
27 May 2026
167 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Hackers exploited a critical zero-day in KnowledgeDeliver to deploy the Godzilla web shell. The unauthenticated flaw (CVE-2026-5426) stems from a shared hardcoded machine key. https://t.co/0zB3krJwI3 #0day #KnowledgeDeliver #Godzilla #CVE #CybersecurityNews #ThreatResQ
@ThreatResq
27 May 2026
84 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2026-5426 2 - CVE-2023-29218 3 - CVE-2026-2031 4 - CVE-2026-41096 5 - CVE-2024-53141 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
26 May 2026
145 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes